How To Fix hijack promlems lxnyg.dll/sp.html#37049


TIP: You should click here to fix Windows errors and optimize system speed.


A DLL file, is a type of file ending in .DLL extension which is a very important type of file in registry of Windows operating system. It can be found in Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 10. When a DLL file goes awry, a nasty DLL error occurs and gives a bad effect to user-experience.

This type of Windows error is giving so much troubles to users since there are a lot of these types of files that can potentially cause problem. The good thing is, there are varied DLL error troubleshooting strategies you can use to identify the real culprit.

From the Forums

A user in the forum details it further:


one of them is for the search page the newdata says res://c:\WINNT\lxnyg.dll/sp.html#37049 this is the hijack log Logfile of HijackThis v1.97.7 Scan saved at 5:33:27 PM, on 6/19/2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVG6\avgserv.exe C:\WINNT\System32\drivers\CDAC11BA.EXE C:\WINNT\System32\svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\VetMsgNT.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\javasn32.exe C:\WINNT\Explorer.EXE C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Visioneer OneTouch\OneTouchMon.exe C:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe C:\ImageMate CompactFlash USB\SandIcon.Exe C:\WINNT\system32\runddl.exe C:\PROGRA~1\WinPatrol.exe C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe C:\WINNT\ipuw32.exe C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\harold senske.HAROLD2\Desktop\hijackthis1977.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Media Player\wmplayer.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://lxnyg.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\lxnyg.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://lxnyg.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\lxnyg.dll/sp.html#37049 O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {13AC38D4-B071-4C58-C3DC-C2FB9CF3C33A} - C:\WINNT\ipuw32.dll O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe O4 - HKLM\..\Run: [SandIcon] C:\ImageMate CompactFlash USB\SandIcon.Exe O4 - HKLM\..\Run: [ControlPanel] C:\WINNT\system32\runddl.exe internat.dll,LoadKeyboardProfile O4 - HKLM\..\Run: [WinPatrol] "c:\PROGRA~1\WinPatrol.exe" O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP O4 - HKLM\..\Run: [ipuw32.exe] C:\WINNT\ipuw32.exe O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: SEARCH (HKLM) O9 - Extra button: ENTERTAINMENT (HKLM) O9 - Extra button: PILLS (HKLM) O9 - Extra button: SECURITY (HKLM) O9 - Extra button: SEARCH (HKLM) O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll Any Ideas jon   I have ran spy bot s&d adaware, hijack this, cwsheader, every time i access internet explorer my spybot pops up with several browser change messages.



What causes hijack promlems lxnyg.dll/sp.html#37049

Fixing a DLL error is an easy task to do especially if you have already identified the specific type of error that’s causing you problems. Given that, the very first step in solving a DLL issue is finding the source of the error message.

Keep in mind that DLL files are non-executable so they require other programs to run. They can be shared or exclusively used by the software that installed them. The idea is to find that software that caused the error. You can examine the error message and keep your focus on the DLL file contained in the message including its path and the software that triggered the error. Once you find the specific cause of the DLL error, it will be easy to apply a fix.

Here are some steps you can do to fix a DLL error:

  1. Restart your computer
  2. Repair damaged/missing DLL files
  3. Use System Restore
  4. Scan your computer for Malwares
  5. Start cleaning Windows Registry
  6. Keep drivers and softwares updated
  7. Uninstall and reinstall affected application
  8. Apply available Windows updates

 

More info on hijack promlems lxnyg.dll/sp.html#37049


RECOMMENDED: Click here to fix Windows errors and optimize system speed.

HiJack This: jilgq.dll/index.html#37049

See my HiJack this log below:

Logfile of HijackThis v1.97.7
Scan saved at 12:44:13 AM, on 6/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\sdkke32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\ntwr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\aim\aim.exe
C:\Program Files\BigFix\BigFix.exe
C:\cwshredder\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\jilgq.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://jilgq.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://jilgq.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\jilgq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://jilgq.dll/index.html#37049
R1 -...


Browser Hijack: res://tgnnm.dll/index.html#37049

I have used the McAfee spyware removal software but it hasn't worked. But at any rate, see if you can work your way thru the step by step procedure for your problem. The URL that appears on my browser is:

res://tgnnm.dll/index.html#37049

Regards

Fred
 




You did not even tell us your OS. You have the HSA hijack.

Here is the procedure: http://forums.majorgeeks.com/showthread.php?t=38772
 




I have had my browser hijacked.


"res://mshp.dll/index.html#37049" -HiJack, they got me.....

reboot again

then post a new hijackthis log to check what is left
 

click "Use custom scanning options>Customize" and have these options on: "Scan within archives" ,"Scan active processes","Scan registry", "Deep scan registry" ,"Scan my IE Favorites for banned URL" and "Scan my host-files"

then......... Make sure the following settings are made and on -------"ON=GREEN"
From main window :Click "Start" then " Activate in-depth scan"

then...... This is the log generated after running Hijack:

Logfile of HijackThis v1.97.7
Scan saved at 10:20:46 AM, on 2/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTSVCCDA.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\NavNT\defwatch.exe
C:\PROGRA~1\DIRECT~1\DUService.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\Program Files\NavNT\rtvscan.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsgSys.EXE
C:\Program...


res://mshp.dll/sp.html#37049

AD-AWARE

Go here: http://www.lavasoftusa.com/support/download/
and download Ad-Aware 6 Build 181

Install the program and launch it. Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Logfile of HijackThis v1.97.7
Scan saved at 2:09:18 PM, on 7/22/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\DELL\AccessDirect\dadapp.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Documents and Settings\mfrankl6\Application Data\etot.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\bjvddqw.exe
C:\Program Files\Messenger\msmsgs.exe
D:\registry_mechanic_ver3.0.0.35_w_cr...


res://pqgad.dll/index.html#37049

is there something new spreading around we don't know about?
 



Here is my hijackthis log. Logfile of HijackThis v1.97.7
Scan saved at 12:39:57 AM, on 6/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mfcby.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\apifj32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pqgad.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://pqgad.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://pqgad.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pqgad.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://pqgad.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pqgad.dll/sp.html#37049
O2 - BHO: ...


Help! res://mgzer.dll/index.html#37049

Now everytime I open IE it has a different homepage. It always seems to change the dll filename portion. I have also downloaded Hijackthis and tried that.....but I didn't fix very many things that it found because I really have no clue what it is telling me!

The current one is res://mgzer.dll/index.html#37049. It was originally changed to res://mshp.dll/index.html#37049 and when I opened IE it would start the windows xp installer dialog box and then ask for my windows xp cd to find some file. So I gave it the cd and it seemed to be content with that. Anyone have any ideas???

I have Ad Aware with the latest updates and I have run that several times and it always finds something, but it isn't curing the home page problem or getting rid of these random popups I keep getting.


HELP:::::: rev://mshp.dll/index.html#37049

Thank you for your support, you are doing a fantastic job! I will wait for your message before continuing with deleting. Messenger (HKLM)
O9 - Extra button: Define (HKLM)
O9 - Extra 'Tools' menuitem: Define (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: Yahoo!

Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38014.2938773148
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540001} - http://download.macromedia.com/pub/shockwave/cabs/fla...


need to get rid of:res://mshp.dll/index.html#37049

I need some help about this problem, I get the "res://mshp.dll/index.html#37049" as my homepage whenever I open the browser. And I have another problem and I don't know if it has to do with the above problem or not. If you choose to end the program immediately you will lose any unsaved data.

Tho return to Windows and check the status of the program click cancel. Each time before turning off the PC or logging off, I'm receiving this popup menu error:

--------------------------------------------------------------------------------------------------

End Program - rundll32.exe

This Program is not responding. Is there someone to guide me through, solving this problem?


res://tcqwc.dll/index.html#37049

I ran the CwShredder and it only found and fixed CWS.Winshow. Below is the Hack This log from the machine after Shredder was run. Anyway... Everytime I start IE it comes up with the Microsoft Office window stating that it is installing components.

Would appreciate any help possible. Logfile of HijackThis v1.97.7
Scan saved at 7:12:33 AM, on 7/6/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\d3zt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\crpv32.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\PROGRA~1\Compaq\EASYAC~1\Bttn...


HELP WITH 'res://amymw.dll/index.html#37049'

Please Help, I have tried ad aware and spybot which don't really do much. Once the tool is done scanning, copy the log and paste it into your thread. with a new Hijack this log.
 

The .dll file in the address bar keeps changing when I try to follow those instructions, and I can't seem to figure out what is causing it to recreate.

Please download this tool called About Buster from:
http://www.atribune.org/downloads/AboutBuster.zip
Created by RubberDucky
Unzip it to your desktop but don't run it yet. Double click Aboutbuster.exe, click OK, click Start, then click OK. Now start Hijackthis and tick the boxes next to these items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50093
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\amymw.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://amymw.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://amymw.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\amymw.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://amymw.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\amymw.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearc...


res://mshp.dll/index.html#37049 ....I have done what I can!!!!

After checking this site at work, especially the thread from e-liam dated Feb 15, 2004, I forwarded the fixes, including CoolWebShredder, Highjack this, Spybot search and destroy, Windows updater and ad-aware. I have attached a hijackthis.log, if anyone cares to take a look and possibly give me any further pointers.

First off...I just want to thank everyone that contributes to this site, you all have help me sort out most of my problems.

I was fortunate that my e-mail operated as I was unable to get my internet explorer operating as it was freezing upon opening on CoolWebsearch. As indicated I was hijacked by CoolWebSearch.


Html#37049 Hijacker problem

Everything AdAware finds is safe to delete. Run SpyBot Search and Destroy --- Make sure you have already gotten the latest UPDATES (Open, then Search for Updates button)
This is where you get SpyBot --- http://www.majorgeeks.com/download2471.html

Empty your Temporary Internet Files and history in Internet Options. Check the following settings:
Scan within archives
Scan active processes
Scan registry
Deep scan registry
Scan my IE Favorites for banned URL
Scan my host-file
Click on Tweak:
Select -- Scanning Engine
Check "Unload recognized processes during scanning"
Check "Include additional Adaware settings in LogFile"
Select -- Cleaning Engine
Check "Automatically try to unregister objects prior to deletion" and "Let windows remove files in use at next reboot"
Then click "proceed" to save your settings. I read a couple of forums about using hijackthis, but that is just way too complicated.

The whole url is " res://purir.dll/index.html#37049 ". Something to read before going on::::::::::::::::::
http://forums.majorgeeks.com/announcement.php?f=35
http://forums.majorgeeks.com/showthread.php?t=35407


Do these free online scans and post what it picked up, plus delete those that are found:
http://housecall.trendmicro.com/housecall/start_corp.asp
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Second Step is to make sure you have all the SpywareProgram...


res://mshp.dll/index.html#37049 PLEASE HELP!!



My home page is reset to res://ghtba.dll/index.html#96676 I have run cwsshredder, adaware, and spybot. Logfile of HijackThis v1.97.7
Scan saved at 5:16:17 PM, on 6/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\winuu.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\CTHELPER.EXE
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\SysAgent\SysAgent.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPMon32.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Juke...


res://mshp.dll/index.html#37049

Okay, close your browser and check the following entry in HJT, click Fix and then REBOOT. O4 - HKLM\..\RunServices: [SystemSAS] system32.exe
After rebooting, find and delete this file:

system32.exe
Now, I don't see any antivirus application running or firewall.

First off, I note that this problem is being discussed in another thread, but I didn't want to 'hijack' that person's thread, so I apologise in advance if I've committed a tech guy sin, and please merge if appropriate. From everything I've read thus far, it looks like the only thing to do is post my hijackthis log and get some genius' help so PLEASE HELP!

You did the right thing starting your own thread. I've also been getting this pop-up page when I do searches in google, as well as a left-hand side bar thingy (?).: http://search-777.com/sec.php?qq=fdfs
Not sure if this is related to the stupid coolwwwsearch crap or some other wonderful disaster all to itself. I have tried a million things to get rid of this crap: spybot, hijackthis, ad-aware, cwshredder, but to no avail.

Good idea to go here for a free online AV scan:

http://housecall.trendmicro.com/housecall/start_corp.asp
 

I know you're waiting for a genuis to help here, but you got me instead.


res://lovcd.dll/index.html#37049

Then check these for fixing:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\lovcd.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://lovcd.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://lovcd.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\lovcd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://lovcd.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\lovcd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {2816A669-5396-432D-C6A2-978A8E8A9E63} - C:\WINDOWS\msnq.dll
O4 - HKLM\..\Run: [atllh32.exe] C:\WINDOWS\system32\atllh32.exe
O4 - HKLM\..\RunOnce: [atlwl.exe] C:\WINDOWS\atlwl.exe
O4 - HKLM\..\RunOnce: [ntrz.exe] C:\WINDOWS\ntrz.exe

next delete in safe mode lovcd.dll, atllh32.exe, atlwl.exe and ntrz.exe
 

Everytime I run internet explorer I get this:
res://lovcd.dll/index.html#37049

And also the windows installer is activated for MS Office XP. I did run all the adware programs possible and still nothing.

Please help
Heres the log:

Logfile of HijackThis v1.97.7
Scan saved at 5:48:14 PM, on 6/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.110...


res://iafsz.dll/index.html#37049

DO NOT have Hijack This fix anything yet. Someone here will be glad to advise you on what to fix.

*Note: When you download Hijack This Do Not download it to a temp folder or to the desktop. Click the "Scan" button when the scan is finished the scan button will become "Save Log" click that and save the log. Most of what it finds will be harmless or even required.

Run Hijack this. Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply. Create a permanent folder somewhere like in My Documents and name it Hijack This and put it in that folder.
 

Click here to download Hijack This.


can't get rid of res://mshp.dll/index.html#37049

Step by step, please! I'm running XP, but beyond that, I don't know what info you'd need to help me. Can anybody help me clean this parasite out?

David
 





res://jvels.dll/index.html#37049

Logfile of HijackThis v1.97.7
Scan saved at 16:37:50, on 30-06-2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAMAS\FICHEIROS COMUNS\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAMAS\FICHEIROS COMUNS\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\HPZSTATX.EXE
C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\ATLQN.EXE
C:\WINDOWS\CRJO32.EXE
C:\WINDOWS\CRJO32.EXE
C:\WINDOWS\SYSTEM\MFCVM32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\AMBIENTE DE TRABALHO\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\jvels.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://jvels.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://jvels.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\jvels.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://jvels.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\jvels.dll/sp.html#37049
O2 - BHO: (...


Solved: HijackThis Log - index.html#37049

Logfile of HijackThis v1.99.1
Scan saved at 5:19:11 PM, on 10/4/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\Samsung\LaserSMMgr\ssmmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe...


Hijacked by res://mshp.dll/index.html#37049



My Home Page has bee Hijacked. Logfile of HijackThis v1.97.7
Scan saved at 10:48:26 PM, on 14/03/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\WINDOWS\DELAYRUN.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\MICROSOFT WORKS\WKSSB.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\HP OFFICEJET SERIES 700\BIN\HPOSTR03.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PALM\HOTSYNC.EXE
C:\PROGRAM FILES\INTEL\CREATESHARE\PROGRAM\PC CAMERA GAMES\PROGRAM\RFTRAY.EXE
C:\WIN...



LATEST TIP: You should click here to fix Windows errors and optimize system speed.



Recommended Links:

(1) Download (hijack promlems lxnyg.dll/sp.html#37049) repair utility.

(2) hijack promlems lxnyg.dll/sp.html#37049

(3) HiJack This: jilgq.dll/index.html#37049

(4) Browser Hijack: res://tgnnm.dll/index.html#37049

(5) "res://mshp.dll/index.html#37049" -HiJack, they got me.....

 
Note: Manual troubleshooting of hijack promlems lxnyg.dll/sp.html#37049 is only recommended for advanced computer users.Download this automatic repair tool instead.